Skip to content

TRULYFORM / PRIVACY

Your work is yours.
We help you look after it.

This Privacy Policy explains what trulyform receives, why we use it, and how control works when you build forms, publish them, or answer one.

Last updated September 18, 2026

This policy applies to the trulyform website, editor, account area, published forms, and related services (together, the “Service”). In this policy, “trulyform”, “we”, “us”, and “our” mean Trulyform operating the Service.

1. The short version

We collect only what we need to run the Service, help you use it, keep it secure, and understand whether it is useful. You decide what to put in a form and who can answer it. If you answer someone else’s form, that form’s creator is normally responsible for deciding why your answers are collected and how they are used; trulyform processes those answers to provide the Service to the creator.

2. Information we receive

  • Account and organization information. Your name, email address, password or sign-in details, organization name, team membership, and security settings.
  • Forms and creator content. Form titles, questions, logic, themes, logos, uploaded assets, publication settings, and drafts.
  • Responses and files. Answers, partial responses, completion details, respondent files, and any other information a creator chooses to collect through a form. A form creator may collect sensitive information, so please read that creator’s own privacy notice before answering.
  • Billing information. Subscription and payment status. Card details are handled by our payment provider rather than stored as full card numbers by trulyform.
  • Messages to us. If you use the contact form, we receive the name, email, company, and message you provide.
  • Technical information. Our hosting, security, and delivery infrastructure may receive information such as IP address, browser and device details, request timestamps, and error or security events.
  • Browser storage. The editor can save drafts in your browser so you can keep working, and a published form can remember a pseudonymous respondent identifier in that browser to support continuity across forms from the same organization. You can clear browser storage through your browser settings.

3. How we use information

  • to create, save, publish, display, and manage forms and responses;
  • to authenticate accounts, support organizations, recover work, and send transactional messages;
  • to process subscriptions, invoices, usage allowances, and payment-related events;
  • to store and deliver creator assets and respondent uploads, including private response files;
  • to prevent abuse, protect accounts and data, troubleshoot failures, and maintain the Service;
  • to answer support and privacy requests; and
  • to understand product usage and improve trulyform, where product analytics is enabled.

Depending on the circumstances and the law that applies to you, these uses may be based on performing our agreement with you, our legitimate interests in operating a secure service, your consent, or a legal obligation.

4. Form creators and respondents

When you create a form, you control the questions you ask, the information you collect, and the people or services with whom you share responses. You are responsible for providing respondents with any notice, consent, instructions, and rights process required for your use of their information.

When you answer a form, contact the organization or person who created it if you have questions about the form, want to access or delete your answers, or want to withdraw permission you gave that creator. We can help route a request when appropriate, but we generally cannot decide what a creator should do with its response data.

5. Service providers

We use carefully selected providers to operate the Service. Depending on the features and deployment in use, these may include:

  • Stripe for subscriptions, checkout, invoices, and payment administration;
  • Google when you choose Google sign-in;
  • Postmark or another configured mail provider for verification, notification, and support email;
  • Cloudflare R2 or another configured storage provider for assets and uploads;
  • PostHog for limited product analytics when it is enabled; and
  • Cloudflare and Sentry for delivery, security, and error reporting when configured.

These providers process information only as needed to provide their services, to comply with law, or as otherwise described in their own privacy notices. We may also disclose information when necessary to comply with law, respond to valid legal process, protect people or the Service, or enforce our agreements.

6. Product analytics

When enabled, trulyform’s product analytics is limited to events such as pages viewed, templates selected, pricing interactions, editor milestones, sign-up progress, and conversion failures. The current configuration does not use session recording, automatic click capture, heatmaps, or external dependency loading. We filter event properties before sending them and do not intentionally send form answers, uploaded files, contact messages, or passwords as analytics events.

7. Retention and deletion

We keep account, organization, form, response, and file data for as long as needed to provide the Service, comply with legal and financial obligations, resolve disputes, and protect the Service. We do not promise to delete responses or respondent files merely because they are partial, old, inactive, or associated with a plan that has changed. Authorized users can delete forms, responses, files, or accounts through the controls available in the Service; deletion may not immediately remove limited copies in backups, logs, or provider systems where retention is required for security, legal, or accounting reasons.

8. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to withdraw consent where consent is the basis for processing. To make a request about information we control, contact us at [email protected]. We may need to verify your identity and may retain information where the law allows or requires it. You may also have the right to complain to your local privacy regulator.

9. Security and international processing

We use technical and organizational safeguards designed to protect information, including authenticated access controls, private response-file access, encrypted connections, and protected credentials. No online service can promise absolute security. Our providers and infrastructure may process information in countries other than the one where you live; where required, we use appropriate legal safeguards for those transfers.

10. Children

The Service is intended for people who can lawfully use it. Do not use trulyform to collect information from children unless you have the permission, notices, and safeguards required by applicable law.

11. Changes and contact

We may update this policy as the Service changes. When a change is material, we will take reasonable steps to bring it to your attention. If you have a privacy question or request, email [email protected] or use the contact page.